Tor Network Compromised by Single Hacker Stealing Users' Bitcoin: Report

The unknown hacker is using Tor exit relays to remove encryption on bitcoin mixer services and change wallet addresses from users to their own.

AccessTimeIconAug 12, 2020 at 5:50 p.m. UTC
Updated Sep 14, 2021 at 9:42 a.m. UTC

A single malicious entity controls nearly a quarter of all nodes used on the anonymous internet provider Tor Network and is using its position to steal bitcoin and other cryptocurrencies.

  • A cybersecurity analyst, using the pseudonym "nusenu," said in a report this week a hacker now controls approximately 23% of the Tor Network's exit relay capacity.
  • The Tor Network provides anonymous internet access with voluntarily run relays that route traffic in order to obfuscate users' traceable and identifiable IP addresses.
  • The exit relay is the final stage that connects users to their requested websites.
  • Per the report, the hacker is using her/his position as a major exit relay host to stage sophisticated person-in-the-middle attacks, stripping websites of encryption and giving her/him full unrestricted access to traffic passing through her/his servers.
  • The malicious agent primarily focused on bitcoin mixer services, replacing wallet addresses so the mixer returns "clean" funds to the hacker rather than the original user.
  • A lack of enforcement on the Tor Network means the hacker has more than doubled her/his share of exit relays from under 10% last December, nusenu said.
  • It's unclear how much cryptocurrency has been stolen and whether the malicious agent is engaged in other attacks.
  • At least one bitcoin mixer service has added an additional security layer preventing hackers from removing their website's encryption.
  • The identity of the hacker remains a mystery and it isn't clear if there's any added motivation is for the attack besides stealing cryptocurrencies.

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Trending

1
CoinDesk - Unknown
A New Chapter of Web3: Solana Unveils Smartphone ‘Saga’; Moody’s Downgrades Coinbase

The most valuable crypto stories for Friday, June 24, 2022.

CoinDesk - Unknown
2
CoinDesk - Unknown
How Are Institutions and Companies Investing in Crypto?

From putting bitcoin on their balance sheets to setting up shop in the metaverse, the ways brands and institutions are investing in cryptocurrencies continues to expand.

CoinDesk - Unknown
3
CoinDesk - Unknown
Consensus 2022: Hollywood, Colleges, Conferences vs. Crypto

The state of crypto and economics live from Consensus 2022 in Austin, Texas.

CoinDesk - Unknown
4
CoinDesk - Unknown
Bitcoin se estabiliza cerca de $21K; inversores esperan evitar otra caída el fin de semana

Los analistas se cuestionan si BTC podrá mantenerse por encima del umbral de $20.000 en un clima de desconfianza entre los inversores.

CoinDesk - Unknown